On 01/04/17 11:10, Dan Broscoi wrote:
> Hi,

Hey!

> Is Bareos SOX compliant ? If not, any special measures can be taken
> to comply ?

I'm not a SOX expert, but I'm betting that the answer is no where near
as simple as "yes" or "no".

I'd think it would depend on how Bareos is configured. If you configure
Bareos with out any encryption and with out strong authentication
between clients and servers (both dir and sd) that Bareos would ring
lots of bells with your SOX auditors.

I do think though that if you configure Bareos with an eye toward
security and reliability that you could actually make your SOX auditors
smile. (If you see this, make sure to take a picture of them. Smiling
auditors are really rare, that photo would probably be worth money!)

Encrypt everything, start right on the client. Setup TLS authentication
between clients and servers.   Document, and TEST, your disaster
recovery procedures. Then have someone else who isn't intimately
familiar with your Bareos configuration test your DR procedures.

I'm sure there are other things also.  Backup solutions don't fail,
people fail.

-- 
You received this message because you are subscribed to the Google Groups 
"bareos-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to